UNC5537
UNC5537 is a financially motivated threat actor tracked by Mandiant and associated with the 2024 Snowflake customer compromises. Mandiant attributed the campaign to UNC5537 and reported that the activity affected roughly 165 Snowflake customer organizations. The actor used stolen credentials obtained from infostealer malware infections to access Snowflake customer environments, with the absence of enforced MFA repeatedly cited as a key enabling factor. Reported infostealers associated with exposed credentials include VIDAR, REDLINE, LUMMA, RISEPRO, RACOON STEALER, and METASTEALER. The group’s activity involved logging into Snowflake customer tenants with valid credentials, often via SnowSight and the SnowSQL CLI, then conducting reconnaissance and large-scale data theft followed by extortion. Mandiant observed UNC5537 using the publicly available database management utility DBeaver Ultimate to connect to and run queries across Snowflake instances. Mandiant also tracked an attacker-named utility, “rapeflake,” as FROSTBITE; observed .NET and Java variants were assessed to perform SQL-based reconnaissance such as enumerating users, roles, IPs, session IDs, and organization names. The campaign was described as relying on customer-side security gaps rather than a Snowflake software vulnerability, specifically missing MFA, unrotated credentials, and lack of network allow-listing. The actor extracted large volumes of sensitive data and extorted victims after exfiltration. Publicly identified victims in the provided content include Ticketmaster, AT&T, Santander, Advance Auto Parts, Neiman Marcus, LendingTree/QuoteWizard, Los Angeles Unified School District, and Pure Storage. The content states that some of the stolen data was later distributed by ShinyHunters, and multiple sources discuss UNC5537 in relation to ShinyHunters. One source describes broader cluster evolution involving UNC5537, UNC6040, UNC6395, and UNC6661 within a ShinyHunters profile, but the provided content does not establish these as formal aliases of UNC5537. Reported pseudonyms used by the actor include “Judische” and “Waifu.” Mandiant reportedly assessed members to be based in North America and Turkey.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster mentioned as part of the cluster evolution associated with the ShinyHunters profile, but no specific operational details are provided in the content.
Financially motivated threat group attributed with the Snowflake campaign, using stolen credentials obtained via infostealer malware to access Snowflake customer tenants, exfiltrate data, and extort victims.
Targeted approximately 165 Snowflake customer organizations using credentials harvested by infostealers in environments lacking enforced MFA, with activity occurring without endpoint-agent detection. The content notes some of the stolen data was later distributed by ShinyHunters.
Financially motivated data theft and extortion activity targeting Snowflake customer environments by using previously stolen Snowflake account credentials (sourced from infostealer malware) to access instances, exfiltrate large volumes of records, and then extort victims; also advertised stolen data for sale on cybercrime forums.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.